Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ggr6-fmr8-2m8g

Опубликовано: 24 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.3
CVSS3: 3.7

Описание

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS

Процентиль: 6%
0.00024
Низкий

6.3 Medium

CVSS4

3.7 Low

CVSS3

Дефекты

CWE-93

Связанные уязвимости

CVSS3: 3.7
msrc
5 дней назад

NGINX ngx_mail_proxy_module vulnerability

EPSS

Процентиль: 6%
0.00024
Низкий

6.3 Medium

CVSS4

3.7 Low

CVSS3

Дефекты

CWE-93